10 ms·
What you're describing is a professional licensed engineer who has to among other things take out insurance because they are ultimately responsible for their de
by iecheruo 6y ago
What you're describing is a professional licensed engineer who has to among other things take out insurance because they are ultimately responsible for their decisions.
- pnathan 6y agoSoftware development is long overdue for a legally professional software engineer license and certification process. I imagine it's going to happen down the road after something important gets burnt.
- Hallucinaut 6y agoThere's no chance of this happening in my view. There's way too many vested interests in the "democratisation of development" especially the likes of "coding bootcamps", limitless frameworks and tools for "code-free" development, and extremely blurred lines on things like WordPress where a "developer" could be anything from someone who can only install plugins through the front-end to crack PHP developers.
- ZephyrBlu 6y agoI think there's more to it than this. In traditional engineering, you only need to be licensed to sign off. You can still effectively do exactly the same job as a licensed engineer without being licensed, you just can't sign off on work (And thus be held responsible). The way I see it, creating a license for Software Engineers doesn't really fix the issue. It just creates a scapegoat to blame when things go wrong.
- ColanR 6y ago> It just creates a scapegoat to blame when things go wrong. That's just how it works for other engineering disciplines; with the license, the scapegoat has the legal power to refuse responsibility until they're confident things won't go wrong.
- ZephyrBlu 6y agoWho is ever really going to be confident in signing off on complicated software systems when in effect, it's saying, "Yes this system will absolutely not break/be breached/have something happen to it". Given the complexity of modern software, it doesn't seem like a feasible solution. Even top software companies have things break or go wrong very frequently compared to traditional engineering. I don't see this as a good solution in the software world.
- oldmanhorton 6y agoI don't think it would demand that the software be infallible. If a "new type of earthquake" happens, the Civil engineers won't be responsible for their bridges failing. In the same way, if there is reasonable effort made to ensure the system is secure by standards of the time, I don't think these theoretical individuals would be blamed for particularly novel (zero day) or unpreventable (social engineering, to at least some extent) attacks.
- raxxorrax 6y agoI learned that protected data is probably safe for a finite timescale with all currently known forms of encryption under the assumption there isn't technological advancement that severely restricts the first assessment.
- james_s_tayler 6y agoAnd they will go wrong. Hey can you put together this trillion piece jigsaw puzzle? Oh and we need you to sign off on it. You're sure it's not going to kill anyone right? Works on my machine!
- frobozz 6y agoThen we need you to sign off on it again after we change it next week, and the week after that.
- batty_alex 6y agoConsidering the number of large, established places that don't even do code reviews - I'm okay with this being a thing.
- Chris2048 6y ago> Oh and we need you to sign off on it Then you say "no". Business "needs" are important for replaceable serfs with no power to say otherwise; when the business needs engineering sign-off, you tell them what they needs to do.
- deleted 6y ago[deleted]
- fotta 6y agoHealthcare.gov was a pretty high profile failure but even then nothing happened after.
- Frost1x 6y agoEquifax also comes to mind... amongst others, but you know. I don't see anything changing as long as it's in money's interest to stay where it is (money rules this country point blank). Right now it's in too many business's interest not to change. There are also slews of developers earning quite a bit who might be forced into career changes depending on how licensing could be implemented.
- jszymborski 6y agoWhile I agree it's overdue, I'm not sure what that event would look like. When a bridge falls down, building collapses, patients die, people take notice. Meanwhile, we've had the social insurance numbers and banking history of 165M+ UK, US, and Canadian people leak out of sheer technical negligence [0], and it resulted in a meek settlement and hardly broke through the public consciousness. It seems to me that until someone dies in a way that is very clearly linked directly to a woefully negligent and under-trained software engineer messing up in a very public way, the needle is not going to budge at all. Perhaps autonomous cars? Even then I doubt it, to be honest. [0] https://en.wikipedia.org/wiki/2017_Equifax_data_breach https://en.wikipedia.org/wiki/2017_Equifax_data_breach
- accrual 6y agoThis reminded me of Therac-25 [0] wherein people died or were seriously harmed by software malfunctions in a radiation therapy machine, and standards were introduced [1] to help mitigate future incidents. [0] https://en.wikipedia.org/wiki/Therac-25 https://en.wikipedia.org/wiki/Therac-25 [1] https://en.wikipedia.org/wiki/IEC_62304 https://en.wikipedia.org/wiki/IEC_62304
- tda 6y agoThat has already happened too with the 737 Max fiasco...
- CamperBob2 6y agoAnd nothing happens at Boeing without being signed off by PE-level engineering staff and management. So is that the remedy people are recommending here?
- pnathan 6y agoI would guess it's about 20 years out, honestly. The sequential and interconnected weight & cost of software failure will have to be well beyond the capacity of conventional errors & omissions insurance to tolerate; settlements will have to be business-crashing - Knight Capital level crashing - to drive this. Today, it's well under that. It is, of course, long overdue; Therac25 should have really gotten the effort going, but, ce la vie with a irresponsible economy. It's plausible the EU legal systems will develop this effort first. I would not be surprised to see France or Germany fully develop the idea, probably in connection with Airbus or Siemens. Anyway. Idealism around quality....
- quantified 6y agoIt can’t be before something important gets burnt. There are a few ash piles out there already.
- bcrosby95 6y agoA huge number of security vulnerabilities are due to production mis-configuration rather than flaws in the development of the actual software. Software Engineers generally aren't trained in managing these production environments so you would probably want at least two different legal licenses to cover your bases.
- PeterStuer 6y agoThe two are not orthogonal. I used to do some work in financial services and some of the systems were designed not to run risks in case of misconfiguration.
- taurath 6y agoSoftware engineers generally aren’t trained in anything, to be completely honest :/
- eru 6y agoMost of them are hired based on their ability to solve simple stand-alone programming puzzles. So you can claim they are trained for that?
- raxxorrax 6y agoI don't think this is a good idea because the issue is the business practice of mindlessly collecting data and not engineering.
- dependenttypes 6y agoWill I be fined if I decide to make my own software without a license?
- CamperBob2 6y agoI'm sure nothing like that could ever happen. /s https://www.vice.com/en_us/article/yw798m/oregon-unconstitutionally-fined-a-man-dollar500-for-saying-i-am-an-engineer-federal-judge-rules https://www.vice.com/en_us/article/yw798m/oregon-unconstitut... Yeah, just what the software industry needs.
- qchris 6y agoEvery time this comes up, people (some of whom are in this thread) end up talking about how this can't/shouldn't happen for software. After all, what, is every high-schooler or green college grad that ever wants to code their own app for a startup going to have to be professional certification? I guess I'd argue that those people shouldn't be legally allowed near this kind of thing without that kind of a certification. Looking into all of the other engineering disciplines, that's exactly the kind of thing you see. I have a BSME, but I haven't taken the Fundamentals of Engineering exam to get my FE cert, in part because getting a PE certification requires working underneath a licensed PE for a certain number of years, which isn't the case for my current job. I also know that by not doing so, there are certain projects that I simply can't work on. I have to imagine that there's a way to create a legally enforceable framework that falls into the same category for software engineers. Want to build a company that creates a digitally-synced notepad? Have at. Want to touch personally-identifiable medical data? Better have a licensed engineer working on that project to sign off, else your company is wide-open to liability claims with teeth. If something unreasonable gets by the signed-off engineer, they're on the hook too. Obviously, it's a complicated problem, and reducing things to a first-order solution rarely is a catch-all, but there has to be some more professional/personal responsibility taken by the individuals building these systems, and a requirement of licensure is a way of empowering engineers in those positions to the point where it actually matters.
- rorykoehler 6y agoWe could run a 2 tier system. Anyone can build apps but to build apps handling sensitive PII you need to be registered. Execs need to be liable for this to work.
- KMag 6y ago> After all, what, is every high-schooler or green college grad that ever wants to code their own app for a startup going to have to be professional certification? You answer your own question fairly well, but I'd add the observation that in licensed engineering domains, we don't always require licensed engineers. We have a licensing regime for structural engineers, but we don't require them for minor structures like gazebos or doghouses. We could have licensed Software Engineers, but only require licensed oversight for software dealing with human lives (avionics, medical devices), PII, elections, and a few other critical cases.
- CamperBob2 6y agoYeah, sounds good, until you have to pay for it. You are willing to pay the costs of "professionalizing" software development and installing expensive gatekeepers, certifications, signoffs, and processes at every step, right?
- pnathan 6y agoYes, I am. Most of that is already in play already after about 30 people are in a group, we as an industry haven't formalized it, and there's no legal teeth around it.
- social_quotient 6y agoYep. And how is this not a standard errors and omissions insurance policy that tech agencies like mine should (are required) be carrying? We spend about 15k per year for about 10mm in coverage (we are a small shop). This sort of oversight is not just an engineering one but it’s fundamental to the core ops of the business. If we are rushing under client pressure (or just running late) to the extent we take on risk to trigger liability, it’s full stop. https://cense.ai/about https://cense.ai/about Guy number two here had the background to know better. Just didn’t make it a priority. It’s unfortunate. The only way things change is when we start seeing data warehousing/collection as a liability (not an asset) and manage it accordingly. And making the penalty for error unforgivable.
- fyfy18 6y agoWorking as a contractor in the UK, most contracts stipulate you have Professional Indemnity insurance, which is for exactly this. I doubt anyone has actually made a claim for it though, the amount of other people I've worked with (who are also contractors earning £500+/day) who I wouldn't trust to even watch my laptop is atrocious.
- Chris2048 6y agoAFAIK, this only really covers gross negligence or outright sabotage. I don't recon anyone trying to pin bad business decisions on their devs are likely to succeed in court.
- jcrawfordor 6y agoWhen I have done independent IT ops and software work I have carried professional liability insurance, and I would recommend that everyone does. The irony is, of course, that PL/E&O insurance for software work runs pretty cheap, presumably because liability on the part of developers of software is quite rare!
- Mandatum 6y agoIn Australia we're all insured. The only developers who aren't are employees for the companies they're writing code for. The worst thing that can happen to them is they'd be fired. The company still owns the blame.